CVE-2026-45223Patch

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-11); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-11: 2Mentions · 2026-05-12: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 2Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 205-1105-12
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-112
Disclosure1Patch1
2026-05-122
Patch2
Full discourse4 posts
  • klawlikula@klawlikula
    Patch

    Two high-severity CVEs to patch now: • CVE-2026-45223 — Crabbox <0.9.0 • CVE-2026-45006 — OpenClaw <2026.4.23 Both are CVSS 8.8, with no active exploitation or PoC reported yet.

    Post summary

    The post highlights two high‑severity CVEs (CVE‑2026‑45223 for Crabbox and CVE‑2026‑45006 for OpenClaw) that require immediate patching, with no exploitation or PoC reported.

    2001059
    3 followersView on X
  • klawlikula@klawlikula
    Patch

    CVE-2026-45223 (Crabbox): an attacker may bypass login checks or gain higher privileges than they should. Fix: upgrade to 0.9.0+.

    Post summary

    The post informs that CVE-2026-45223 allows privilege escalation and provides a simple patch recommendation.

    0000022
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45223 Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to rej… https://www.cve.org/CVERecord?id=CVE-2026-45223

    Post summary

    The text announces a new authentication bypass vulnerability in Crabbox before 0.9.0, with brief technical details, but provides no PoC, exploit, or patch information.

    0000053
    57.5K followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 HIGH: CVE-2026-45223 in Crabbox <0.9.0. Authentication bypass in verifyUserToken() allows privilege escalation to full admin access via crafted HMAC-SHA256 token with admin:true claim. Patch now. https://0x2ed3bb60.xyz/threat/fff77f4b395a42ee

    Post summary

    The post alerts to a high‑severity authentication bypass in Crabbox (<0.9.0) that allows privilege escalation via tampered HMAC tokens and urges users to apply the available patch.

    0000033
    7 followersView on X

Explore more